CVE-2024-27448: MailDev Remote Code Execution
MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js
writing arbitrary code into the routes.js
file.
References
Detect and mitigate CVE-2024-27448 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →